Privacy Policy
Last updated: July 7, 2026
This policy explains what personal data TokenSkim processes, why, and your rights under the EU General Data Protection Regulation (GDPR).
Data controller
The data controller responsible for your personal data is:
Redbit S.r.l.s.
Viale della Grande Muraglia, 494, 00144 Roma (RM), Italy
REA RM1576999 · VAT IT15237911001
PEC: [email protected]
Contact: [email protected]
The most important point first
When you use the free analyzer, your usage export file is parsed entirely inside your browser. The file and its contents are never transmitted to, uploaded to, or stored on our servers. We cannot see your usage data.
What we process, and why
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Analytics & usage (via Google Analytics 4) — pseudonymous device and interaction data, with IP anonymized | Understand how the site is used and improve it | Consent (Art. 6(1)(a)), collected via our consent banner |
| Aggregate, anonymous page metrics via our own self-hosted, cookieless analytics — no cookies and no personal data (visitor identity is never stored) | Measure traffic in aggregate and detect outages | Legitimate interest (Art. 6(1)(f)) |
| Contact data (email address) when you write to us | Respond to your request | Legitimate interest / pre-contractual steps |
| Order & billing data for paid services (name, email, billing details, VAT ID) — card data is handled directly by Stripe, we never receive it | Provide and invoice paid audits and monitoring; meet tax obligations | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Monitoring account data — your email (sign-in via magic link) and your provider admin API key, stored encrypted at rest (AES-256-GCM); usage is aggregated, not personal | Deliver the ongoing Monitoring service and its periodic reports | Performance of a contract (Art. 6(1)(b)) |
| Newsletter data — email address and proof of consent (timestamp, double opt-in) | Send product updates and cost-saving tips you asked for | Consent (Art. 6(1)(a)) — double opt-in, withdrawable anytime |
| Technical logs and error data (IP address, user agent, timestamps, technical error context) | Security, abuse prevention, diagnosing faults, operating the service | Legitimate interest (Art. 6(1)(f)) |
Service providers (processors) and third parties
We rely on the following providers, who process data on our behalf or as independent controllers:
- Google (Google Analytics 4) — analytics, only after your consent.
- InMobi (Choice CMP) — manages your consent choices (IAB TCF v2.2). For the consent signals, InMobi acts as a joint controller.
- Stripe — payment processing for paid services.
- Cloudflare — content delivery, DNS, security, and anti-spam (Turnstile) on our forms.
- Sentry — error monitoring, configured to exclude personal data.
- IONOS — hosting of our dedicated server (in the EU, Germany).
- Our self-hosted email and newsletter infrastructure — to receive and answer your messages and to send the newsletter you opted into.
Some providers (Google, Stripe, Cloudflare, Sentry, InMobi) may process data outside the EEA. Where this happens, transfers are covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. Our hosting, email and newsletter infrastructure runs on servers located in the EU.
Retention
- Order & billing data: for the period required by tax and accounting law (10 years under Italian law).
- Analytics (GA4): per our Google Analytics configuration (up to 14 months); aggregate cookieless metrics are not tied to any individual.
- Contact messages: up to 24 months after our last exchange.
- Newsletter: until you unsubscribe or withdraw consent; proof of consent is kept for accountability.
- Monitoring account: for the life of your account; your data and encrypted API key are deleted on request or when the account is closed.
- Technical logs & error data: a limited period for security (error data around 90 days).
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict or object to the processing of your personal data, to data portability, and to withdraw consent at any time (without affecting prior processing). To exercise these rights, contact us at [email protected]. You also have the right to lodge a complaint with your supervisory authority — in Italy, the Garante per la protezione dei dati personali.
Newsletter
If you subscribe, we use double opt-in: you confirm via a link we email you before we send anything. We only use your address to send the newsletter, and you can unsubscribe at any time from the link in every email or by contacting us.
Cookies
For details on cookies and similar technologies, see our Cookie Policy. You can change your choices at any time via the "Cookie settings" link in the footer.
Changes
We may update this policy. The current version is always available on this page, with the date shown above.